Listing of Claims: 



IN THE CLAIMS 



1-4. (Cancelled) 

5. (Currently Amended) A method of controlling access to data on a computer, the 
method comprising: 

storing a list of valid token values: 

accepting a request for a data item, wherein the request contains a nonc o va l uo, 
wherein th e nonc o valu o comprises a received token value that is only accepted for a 
specified number of requests; 

determining that-the nenee -the received token value is within the list of valid 
token values is-^atid and has been accepted for fewer than the specified number of 
requests; 

removing, in response to determining the received token value has been 
accepted for the specified number of reguests, the received token value from the list of 
valid token values: and 

responding to the request by returning the data item in response to the 
determining that the nonco received token value is valid within the list of valid token 
values and has been accepted for fewer than the specified number of requests. 

6. (Currently Amended) The method according to claim 5, further comprising: 
charging an entity in response to returning the data item in conjunction with the 

use of the nonco token value. 

7. (Currently Amended) The method according to claim 5, wherein tho nonco valu o 
eompr i s e s token values within the list of valid token values and the received token value 
comprise an expiration time and wherein the determining further determines that the 
fleftee -received token value has not expired. 

8. (Cancelled) 



POU920010113US1 



2 of 12 



09/976,524 



9. (Currently Amended) The method according to claim S5, wherein the list of 
stor e d and valid nonc e token values is shared with an entity that originated the data 
request. 

10-15. (Cancelled). 

16. (Currently Amended) A system for controlling access to data on a computer, the 
system comprising: 

a request receiver for accepting a request for a data item, wherein the request 
contains a nonco va l ue, and whoroin tho nonco valuo comprises a token value that is 
only accepted for a specified number of requests; 

a nonco token verifier storing a list of valid token values, for determining that the 
nonco received token value is within the list of valid token values valid and has been 
accepted for fewer than the specified number of requests , and for removing, in 
response to determining the received token value has been accepted for the specified 
number of requests, the received token value from the list of valid token values : and 

a response generator for responding to the request by returning the data item in 
response to the determining that the fleftee -received token value is vaM within the list 
of valid token values and has been accepted for fewer than the specified number of 
requests. 

1 7. (Currently Amended) The system according to claim 1 6, further comprising: 

a billing module for charging an entity in response to returning the data item in 
conjunction with the use of the nonc e token value. 

1 8. (Currently Amended) The system according to claim 1 6, wherein the nonce v a lu o 
compr i ses token values within the list of valid token values and the received token value 
comprise an expiration time and wherein the flenee -token verifier further determines 
that the nonco received token value has not expired. 

19. (Cancelled). 
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20. (Currently Amended) The system according to claim 4916, wherein the stor e d list 
of valid nonc e token values is shared with an entity that originated the data request. 

21-26. (Cancelled). 

27. (Currently Amended) A computer readable medium including computer 
instructions for controlling communications access to computer, the computer 
instructions comprising instructions for: 

storing a list of valid token values: 

accepting a request for a data item, wherein the request conta i ns a nonc o va l u e , 
wh e r ei n th e n o nc e va l u e comprises a received token value that is only accepted for a 
specified number of requests; 

determining that-the m^oe -the received token value is within the list of valid 
token values is-valid and has been accepted for fewer than the specified number of 
requests; 

removing, in response to determining the received token value has been 
accepted for the specified number of reouests. the received token value from the list of 
valid token values; and 

responding to the request by returning the data item in response to the 
determining that the nonco received token value is vaM within the list of valid token 
values and has been accepted for fewer than the specified number of requests. 

28. (Currently Amended) The computer readable medium according to claim 27, 
further comprising instructions for: 

charging an entity in response to returning the data item upon use of the nonc e 
token value. 

29. (Currently Amended) The computer readable medium according to claim 27, 
wherein tho nonco valu e compr i ses token values within the list of valid token values and 
the received token value comprise an expiration time and wherein the instructions for 
determining further comprise instructions for determining that the nonc e received token 
value has not expired. 
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30. (Cancelled). 



31. (Currently Amended) The computer readable medium according to claim 3027, 
wherein the list of stored and valid f^nee -token values is shared with an entity that 
originated the data request. 

32-33. (Cancelled). 

34. (Currently Amended) The method of claim 5, wherein the nonco token value is 
only accepted one time, and wherein the responding to the request is performed in 
response to the nonee- token value having not been previously accepted. 

35. (New) The method of claim 7, further comprising: 

periodically generating, with a period, a respective new list of valid token values; 

sending, in response to the periodically generating, the new list of stored and 
valid token values to the associated computer, 

wherein a respective expiration time of each token value in the new list of valid 
token values is based upon the period so as to cause generation of the respective new 
list of valid token values prior to expiration of previously generated valid token values. 

36. (New) The method of claim 5, further comprising: 
generating the list of valid token values; and 

sending, in response to the generating, the list of valid token values to an 
associated computer. 

37. (New) The method of claim 36, wherein the token value has been signed by the 
associated computer, and wherein the determining that the token value is valid and has 
been accepted for fewer than the specified number of requests comprises verifying the 
signed token value. 
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